Fwd: [Errata Rejected] RFC6487 (3168)
2013-05-06 12:30:32 GMT
Whilst this change was supported by one author and one of the chairs,
it is a technical change and thus outside the scope of change
permitted in an errata.
The correct approach is for a member of the WG to produce a
short update draft and test that this has WG and IETF consensus.
Please can the chairs drive this process.
- Stewart
-------- Original Message --------
| [Errata Rejected] RFC6487 (3168) |
| Mon, 6 May 2013 05:24:39 -0700 |
| RFC Errata System <rfc-editor <at> rfc-editor.org> |
| <dmandelb <at> bbn.com>, <gih <at> apnic.net>, <ggm <at> apnic.net>, <robertl <at> apnic.net> |
| <stbryant <at> cisco.com>, <iesg <at> ietf.org>, <rfc-editor <at> rfc-editor.org> |
The following errata report has been rejected for RFC6487, "A Profile for X.509 PKIX Resource Certificates". -------------------------------------- You may review the report below and at: http://www.rfc-editor.org/errata_search.php?rfc=6487&eid=3168 -------------------------------------- Status: Rejected Type: Technical Reported by: David Mandelberg <dmandelb <at> bbn.com> Date Reported: 2012-03-26 Rejected by: Stewart Bryant (IESG) Section: 4.8 Original Text ------------- or non-critical. A certificate-using system MUST reject the certificate if it encounters a critical extension it does not recognize; however, a non-critical extension MAY be ignored if it is not recognized [RFC5280]. Corrected Text -------------- or non-critical. A certificate-using system MUST reject the certificate if it encounters an extension not explicitly mentioned in this document. This is in contrast to RFC 5280 which allows non-critical extensions to be ignored. Notes ----- Other sections of the same document contradict the original section 4.8: Section 1: Any extensions not explicitly mentioned MUST be absent. The same applies to the CRLs used in the RPKI, that are also profiled in this document. Section 8: Certificate Extensions: This profile does not permit the use of any other critical or non-critical extensions. --VERIFIER NOTES-- This is a technical change to the RFC and needs to be addressed though the IETF consensus process and rather than via the errata process. -------------------------------------- RFC6487 (draft-ietf-sidr-res-certs-22) -------------------------------------- Title : A Profile for X.509 PKIX Resource Certificates Publication Date : February 2012 Author(s) : G. Huston, G. Michaelson, R. Loomans Category : PROPOSED STANDARD Source : Secure Inter-Domain Routing Area : Routing Stream : IETF Verifying Party : IESG .
<div>
<br>Whilst this change was supported by one author and one of the
chairs,<br>
it is a technical change and thus outside the scope of change<br>
permitted in an errata.<br><br>
The correct approach is for a member of the WG to produce a <br>
short update draft and test that this has WG and IETF consensus.<br><br>
Please can the chairs drive this process.<br><br>
- Stewart<br>
<div class="moz-forward-container">
<br><br>
-------- Original Message --------
<table class="moz-email-headers-table" border="0" cellpadding="0" cellspacing="0">
<tr>Subject:
<td>[Errata Rejected] RFC6487 (3168)</td>
</tr>
<tr>Date:
<td>Mon, 6 May 2013 05:24:39 -0700</td>
</tr>
<tr>From:
<td>RFC Errata System <a class="moz-txt-link-rfc2396E" href="mailto:rfc-editor <at> rfc-editor.org"><rfc-editor <at> rfc-editor.org></a>
</td>
</tr>
<tr>To:
<td>
<a class="moz-txt-link-rfc2396E" href="mailto:dmandelb <at> bbn.com"><dmandelb <at> bbn.com></a>, <a class="moz-txt-link-rfc2396E" href="mailto:gih <at> apnic.net"><gih <at> apnic.net></a>,
<a class="moz-txt-link-rfc2396E" href="mailto:ggm <at> apnic.net"><ggm <at> apnic.net></a>, <a class="moz-txt-link-rfc2396E" href="mailto:robertl <at> apnic.net"><robertl <at> apnic.net></a>
</td>
</tr>
<tr>CC:
<td>
<a class="moz-txt-link-rfc2396E" href="mailto:stbryant <at> cisco.com"><stbryant <at> cisco.com></a>, <a class="moz-txt-link-rfc2396E" href="mailto:iesg <at> ietf.org"><iesg <at> ietf.org></a>,
<a class="moz-txt-link-rfc2396E" href="mailto:rfc-editor <at> rfc-editor.org"><rfc-editor <at> rfc-editor.org></a>
</td>
</tr>
</table>
<br><br>The following errata report has been rejected for RFC6487,
"A Profile for X.509 PKIX Resource Certificates".
--------------------------------------
You may review the report below and at:
<a class="moz-txt-link-freetext" href="http://www.rfc-editor.org/errata_search.php?rfc=6487&eid=3168">http://www.rfc-editor.org/errata_search.php?rfc=6487&eid=3168</a>
--------------------------------------
Status: Rejected
Type: Technical
Reported by: David Mandelberg <a class="moz-txt-link-rfc2396E" href="mailto:dmandelb <at> bbn.com"><dmandelb <at> bbn.com></a>
Date Reported: 2012-03-26
Rejected by: Stewart Bryant (IESG)
Section: 4.8
Original Text
-------------
or non-critical. A certificate-using system MUST reject the
certificate if it encounters a critical extension it does not
recognize; however, a non-critical extension MAY be ignored if it is
not recognized [RFC5280].
Corrected Text
--------------
or non-critical. A certificate-using system MUST reject the
certificate if it encounters an extension not explicitly mentioned
in this document. This is in contrast to RFC 5280 which allows
non-critical extensions to be ignored.
Notes
-----
Other sections of the same document contradict the original section 4.8:
Section 1:
Any extensions not explicitly mentioned MUST be absent. The same
applies to the CRLs used in the RPKI, that are also profiled in this
document.
Section 8:
Certificate Extensions:
This profile does not permit the use of any other critical or
non-critical extensions.
--VERIFIER NOTES--
This is a technical change to the RFC and needs to be addressed though the IETF consensus process and rather than via the errata process.
--------------------------------------
RFC6487 (draft-ietf-sidr-res-certs-22)
--------------------------------------
Title : A Profile for X.509 PKIX Resource Certificates
Publication Date : February 2012
Author(s) : G. Huston, G. Michaelson, R. Loomans
Category : PROPOSED STANDARD
Source : Secure Inter-Domain Routing
Area : Routing
Stream : IETF
Verifying Party : IESG
.
<br>
</div>
<br>
</div>

RSS Feed